>_devtools

PEM to JWK and JWK to PEM Converter

Convert RSA, EC, and Ed25519 keys and certificates between PEM and JWK in both directions, with optional kid, use, and alg, and RFC 7638 thumbprints.

What this does

Servers and OpenSSL speak PEM; JOSE libraries, OIDC providers, and JWT tooling speak JWK. This converter moves keys between the two in either direction. It uses the browser's WebCrypto key import and export, so the output is exactly what an engine would produce, not a hand-rolled encoding.

PEM to JWK

  • Accepts PKCS#8 (PRIVATE KEY), PKCS#1 (RSA PRIVATE KEY, RSA PUBLIC KEY), SEC1 (EC PRIVATE KEY), SPKI (PUBLIC KEY), and also certificates and CSRs, from which the public key is taken.
  • RSA, EC (P-256, P-384, P-521), and Ed25519 keys (X25519 where the browser supports it). Several blocks produce a JWKS.
  • Optionally add kid (a custom value or the RFC 7638 thumbprint), use, and alg.
  • Encrypted keys are not decrypted. The tool tells you to decrypt them first, for example with openssl pkcs8 -in key.pem -out plain.pem.

JWK to PEM

Paste a JWK or a whole JWKS. Each key is converted separately; a bad entry is reported without blocking the rest. Private keys can be written as PKCS#8, or as PKCS#1 (RSA) or SEC1 (EC) for tools that still expect the older formats. The public half is always available as SPKI or PKCS#1. RSA private JWKs need the CRT members (p, q, dp, dq,qi); the error tells you which are missing. Symmetric oct keys have no PEM form.

Not supported

Curves WebCrypto lacks (secp256k1, Ed448, Brainpool) are reported as unsupported rather than converted unreliably, and OpenSSH-format private keys must first be converted withssh-keygen -p -m PKCS8.

Privacy

Conversion happens in your browser. Keys are held in memory only, never uploaded, stored, or placed in the URL.